Sceawere

Vulnerability Detail

CVE-2026-86276UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hard-Coded Credentials in Syllabus-Aligned LMS

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
SourceCodester
Product
Syllabus-Aligned Learning Management & Examination System
Attack Type
Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-07T06:17:24.173Z",
  "pubdate": "2026-09-07T06:17:24.173Z",
  "executiveSummary": "The Syllabus-Aligned Learning Management & Examination System 1.0 contains a critical security vulnerability involving the storage of hard-coded credentials within the db.php file.\nThis flaw allows remote attackers to bypass standard authentication mechanisms by leveraging the embedded credentials to access the backend database or administrative functionalities.\nThe vulnerability represents a significant risk to the confidentiality, integrity, and availability of the system, as unauthorized parties can gain full control over sensitive academic and student data.\nThe exposure is exacerbated by the fact that exploits for this vulnerability are publicly available, increasing the likelihood of successful automated or manual attacks.\nNo authentication is required to initiate the attack, as the hard-coded values are accessible through direct interaction with the application's configuration parameters or script execution paths.\nOrganizations deploying this version are at immediate risk of data exfiltration and system compromise, necessitating urgent remedial actions to secure the database configuration and credential management practices.",
  "technicalDetails": "The vulnerability originates from the insecure implementation of database connection management within the file path 'db.php'. Analysis indicates that the application utilizes hard-coded credentials, such as plaintext usernames and passwords, for database authentication rather than utilizing environment variables or secure configuration management systems.\nBecause the 'db.php' file is part of the core operational framework, the exposure of these credentials occurs during standard system initialization and database connectivity processes.\nThe attack flow begins with an external actor identifying the reachable 'db.php' file or intercepting configuration responses that disclose the embedded authentication tokens. Since the credentials are hard-coded, they remain static across all deployments of version 1.0, enabling attackers to craft specific payloads targeting the underlying database management system (e.g., MySQL or MariaDB).\nUpon successful identification of these credentials, an attacker can establish an unauthorized remote connection to the database server if the database port is exposed to the network, or leverage these credentials within the web application context to elevate privileges and bypass login interfaces.\nThe impact of this exploitation is comprehensive; successful attackers can perform arbitrary data manipulation, execute unauthorized queries, exfiltrate sensitive user records, or modify academic content within the Syllabus-Aligned Learning Management & Examination System.\nThe exploit's remote nature means that no local presence or user interaction is required to trigger the vulnerability. The post-exploitation phase typically involves establishing persistence, such as injecting administrative user accounts into the database or deploying webshells if the database configuration permits file-write operations (e.g., SELECT ... INTO OUTFILE).\nThe inclusion of these hard-coded credentials in the source code constitutes a fundamental failure in secure development lifecycle (SDL) practices, specifically regarding sensitive data exposure and configuration management."
}
CVE-2026-86276: Hard-Coded Credentials in Syllabus-Aligned LMS (HIGH Severity, CVSS: 7.3) - Sceawere